suryasaradhi
cbbb83073f
Added Authors
2021-10-05 21:03:45 +05:30
adfoster-r7
9884634d0b
Land #15744 , update description, refs, and rubocop on tomcat_jsp_upload_bypass
2021-10-05 10:25:47 +01:00
h00die
d9d3204e1c
update description, ref, rubocop
2021-10-04 22:14:51 -04:00
surya
48388133dd
Msftidy up code v2
2021-10-05 02:33:36 +05:30
surya
171f114ce2
Msftidy up code v1
2021-10-05 02:10:33 +05:30
surya
3461c7aef6
Added module for CVE-2021-40444
2021-10-05 01:44:34 +05:30
sjanusz
2c7aa022d4
Add PoC for CVE-2021-22555 Netfilter Priv Escalation
2021-10-04 16:48:23 +01:00
h00die
f49d817ac4
working on cd
2021-10-03 16:13:38 -04:00
Spencer McIntyre
d8f2b18649
Implement review feedback
2021-10-01 14:44:13 -04:00
Spencer McIntyre
8d82bebc3c
Add the kubernetes/exec module docs
2021-10-01 10:32:12 -04:00
Spencer McIntyre
32540247cb
Move the Kubernetes client into a library file
2021-10-01 10:32:12 -04:00
Spencer McIntyre
d135e7677b
Fix a couple of bugs in the k8s/exec module
2021-10-01 10:32:12 -04:00
Spencer McIntyre
250e40762d
Add the ability to create a new pod
2021-10-01 10:32:06 -04:00
adfoster-r7
a7aa255389
Update gitea git hooks rce check method
2021-10-01 01:11:11 +01:00
Spencer McIntyre
7e62ab92ce
Allow configuration via an established session
2021-09-30 16:54:01 -04:00
Spencer McIntyre
ea6761a3fa
Module cleanup and error handling
2021-09-30 16:54:01 -04:00
Spencer McIntyre
eb1507660f
Add support for direct websocket sessions
2021-09-30 16:54:01 -04:00
Spencer McIntyre
7536db1702
Add an initial kubernetes exec module
2021-09-30 16:54:01 -04:00
kalba-security
6b4aa25490
Add Meterpreter support via Linux target with ARCH_ARMLE and cmdstager
2021-09-23 18:26:13 -04:00
space-r7
64f7581c97
Land #15686 , OptRegexp default should be string
2021-09-23 09:22:45 -05:00
kalba-security
af98d56e17
Update credits to add PoC
2021-09-23 06:22:39 -04:00
kalba-security
0d42c36655
Specify that newer versions may still be vulnerable as no patch has been confirmed by the vendor
2021-09-23 05:19:07 -04:00
kalba-security
b81d44020a
Add Aerohive NetConfig 10.0r8a LFI and log poisoning to RCE module and docs
2021-09-23 04:57:48 -04:00
space-r7
b24b6d8063
Land #15695 , fix crash / add logging nmap module
2021-09-21 14:13:11 -05:00
adfoster-r7
c86f52a3ec
Land #15679 , bug fix for tomcat_mgr_upload module not undeploying app after exploit
2021-09-21 03:34:43 +01:00
adfoster-r7
ed72ca217a
Improve setuid nmap module
2021-09-21 01:47:59 +01:00
space-r7
fee037ac18
Land #15670 , add opmanager sumpdu deser module
2021-09-20 12:15:26 -05:00
Jeffrey Martin
731b3d5ffe
OptRegExp default value as string representation
...
OptRegExp default should be string to utilize in a Regex.
This allows for the object to serialize in metadata and via
rpc bridge when transimiteed using msgpack.
2021-09-17 16:34:46 -05:00
Spencer McIntyre
4bccc0541f
Add a note about exploitable versions
2021-09-16 17:08:23 -04:00
Spencer McIntyre
fd0f565095
Add automatic targeting for the CVEs
2021-09-16 15:15:52 -04:00
space-r7
12af64c4d8
Land #15604 , add buffer overflow G-Cam module
2021-09-16 13:02:57 -05:00
Spencer McIntyre
9f971e8716
Update the module for CVE-2021-3287
2021-09-16 12:58:30 -04:00
Your Name
a2f83c22ba
Add Pattern Create
2021-09-16 08:22:57 +01:00
Naveen Sunkavally
d1da74d329
bug fix to undeploy app after exploit
2021-09-15 21:54:21 -04:00
Spencer McIntyre
56cd43a8b8
Land #15624 , Add module for CVE-2020-27955
2021-09-15 14:54:19 -04:00
Spencer McIntyre
fb74888a31
Correct the CVE reference
2021-09-15 08:42:55 -04:00
Spencer McIntyre
1bd3a764a6
Fixup issues from testing
2021-09-14 16:32:25 -04:00
Spencer McIntyre
480dec9a1e
Land #15658 , Add module for CVE-2021-32682
2021-09-14 14:09:27 -04:00
space-r7
278807be98
check contents of json after attempted upload
2021-09-14 11:36:28 -05:00
Spencer McIntyre
d82ed7d4a2
Write up the module docs
2021-09-14 09:10:44 -04:00
Spencer McIntyre
3986707895
Add and test the remaining targets
2021-09-14 09:10:44 -04:00
Spencer McIntyre
d640866b68
Apply rubocop changes and fix all targets
2021-09-14 09:10:44 -04:00
Spencer McIntyre
d4834631c3
Add the generated YSoSerial gadget chain
2021-09-14 09:10:44 -04:00
Spencer McIntyre
02fde3ac51
Initial work on CVE-2021-3287
2021-09-14 09:10:44 -04:00
adfoster-r7
1499b1988e
Land #15609 , Add Meterpreter compatibility commands
2021-09-13 15:21:03 +01:00
adfoster-r7
46718e3390
Run Rubocop layout rules on modules
2021-09-10 12:53:39 +01:00
space-r7
91ae50eb27
escapeshellcmd -> escapeshellarg
2021-09-09 17:28:05 -05:00
space-r7
0095613a94
add completed module and documentation
2021-09-09 16:58:40 -05:00
adfoster-r7
059e39a6f0
Specify meterpreter compatibility command requirements
2021-09-08 22:59:25 +01:00
William Vu
8c4e5d262c
Add Atlassian Confluence CVE-2021-26084 exploit
2021-09-08 06:57:31 -05:00